Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
RabbitMQ: Stream listener does not enforce configured frame-size limit during authentication, permitting unauth'd mem-exhaust DoS
Vulnerability Description
RabbitMQ is a messaging and streaming broker. Prior to 4.2.6, the RabbitMQ stream listener does not enforce the configured stream frame-size limit while assembling frames during authentication and before Tune negotiation, allowing an unauthenticated remote client to declare oversized frame lengths and consume broker memory in rabbit_stream_core. This issue is fixed in version 4.2.6.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Vulnerability Type
不加限制或调节的资源分配
Vulnerability Title
rabbitmq-server 资源管理错误漏洞
Vulnerability Description
RabbitMQ rabbitmq-server是RabbitMQ组织的消息队列中间件。 rabbitmq-server 4.2.6之前版本存在资源管理错误漏洞,该漏洞源于流监听器在身份验证和Tune协商期间未强制执行配置的流帧大小限制,可能导致未经身份验证的远程客户端声明超大帧长度并消耗rabbit_stream_core中的代理内存。以下版本受到影响:4.2.0版本至4.2.6之前版本。
CVSS Information
N/A
Vulnerability Type
N/A